Buffer Underwrite Vulnerability in OP-TEE OS by Linaro
CVE-2026-71969

8.4HIGH

Key Information:

Vendor

Op-tee

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-71969?

The OP-TEE OS, up to version 4.10.0, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations. This flaw resides within the mbedTLS software backend and the SE050 hardware driver. An attacker exploiting this vulnerability can provide input lengths that exceed the RSA modulus size, leading to heap memory corruption in the secure world. Specifically, when the source length surpasses the RSA length, it causes the subtraction operation to wrap into a large unsigned value, allowing the memcpy function to overwrite secure memory with attacker-controlled data. Prompt action is advised to mitigate potential security risks.

Affected Version(s)

optee_os 0 <= 4.10.0

optee_os 0 <= 4.10.0

optee_os 7b8b494e0a324cefec8ed386b7de413b44f1aaf3

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramtine Tofighi Shirazi (Secmate.dev)
Argus Systems - ByteRay Ltd.
.